Lucene search

K
redhatcveRedhat.comRH:CVE-2020-10684
HistoryApr 09, 2020 - 10:37 a.m.

CVE-2020-10684

2020-04-0910:37:24
redhat.com
access.redhat.com
17

0.0004 Low

EPSS

Percentile

14.2%

A flaw was found in the Ansible Engine. When using ansible_facts as a subkey of itself, and promoting it to a variable when injecting is enabled, overwriting the ansible_facts after the clean, an attacker could take advantage of this by altering the ansible_facts leading to privilege escalation or code injection. The highest threat from this vulnerability are to data integrity and system availability.

Mitigation

Currently, there is not a known mitigation except avoiding the functionality of using ansible_facts as a subkey.